Cottage Health System
bd_99ad03604447cdd0 · schema v1 · pii pii-v1
Full breach record for Cottage Health System →2 incidents on fileCottage Health System disclosed that a third-party vendor removed electronic security protections from a server, exposing patient health information including diagnoses and lab results. The incident was discovered on December 2, 2013, when the organization received a voicemail indicating the data was accessible via Google. The server was immediately taken offline, and the organization offered identity theft protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2013
Discovered
Dec 11, 2013
Filed
vs. sector median
11 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCR enforcementbd_6a0d30e29c3c87b72019-02-07 · +1884dVerified by operator
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Dec 11 (CA), last Feb 7 — a 1884-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.